I recently passed GXPN with great score (96%) and here I write my review about the course and the exam.
SANS/GIAC is the most informative and prestigious training/certification in information security industry. GXPN is the most advanced certification in Penetration Testing offered by SANS/GIAC.
My Background
I’ve almost 7 years experience in Penetration Testing and almost 75% hands-on and scattered knowledge of the course syllabus.
SANS 660 Course
SEC 660: Advanced Penetration Testing, Exploit Writing, and Ethical Hacking is the course for GXPN. The course is very informative and giving almost everything you want to start writing finding vulnerabilities and writing exploits.
The course has 6 days where:
Day 1: This day talks mainly network level attacks starting with bypassing NAC, MitM attacks, routing protocols attacks, SNMP, network manipulation and others.
Day 2: This day talks about crypto algorithms and attacks then it goes back to network booting attacks, then Powershell for penetration testers and finally attacks on restricted environment like Kios, SRP and AppLocker.
Day 3: Here things are getting more difficult. This day talks about Python, Scapy, Sulley and other fuzzing tools.
Day 4: This day talks about Linux exploitation, but it starts with introduction about memory and CPU especially in Linux.
Day 5: This day talks about Windows exploitation and anti-exploitation techniques.
Day 6: Bootcamp (CTF).
GXPN Exam
The exam is objective with about 60 questions. There are 7 lab exams where I had access to remote desktop in order to be able to figure out the answer.
The exam is open book and I had prepared two indexes for it. The first is about every tool used in the course, the usage and the page number. The other index, is the term index.
I had two practical tests before the real attempt, for the first practical test I decided to take it to measure my understanding for the course so I set immediately after the course and without the books and without preparing my index. I got 89% score which was very promising for me.
I needed about 10 days to go through the books and build my indexes. Then I set for the second practical exam with the index and the books. I got 87% this time which also gave the confidence that I am well prepared for the exam so I scheduled the exam.
In the exam, I’ve my the following with me:
– The books
– PE File format
– TCP/UDP common ports
– Metasploit Meterpreter commands
I’ve finished the exam after 2 hours and 30 minutes and got 96% score :D.
SANS Advisory Board
In the same day, I got an invitation from SANS to join their advisory board as I got high score in GXPN.
Hi man.Can you share your index with me? I’m going to take gxpn exam end of this year 2017. Any tips?
Hi sir.I’m Zack from Malaysia.Can you share your index with me for SANS sec660 GXPN Exam?
Done… at your won risk.
thanks man but i can’t find in my inbox. what is your email address?
I scheduled the exam for October, can you share your index with me please?
Done… at your own risk.
Hey man how are you doing.
thank you for the GXPN review, it was useful for me.
i attended the course, its amazing, and i would like to know if you have a walk-through for the last challenge in day 4 which is about developing an explaoit for ret2libc_aslr as i need to understand it very well.
really appreciate your help in advance.
Hi Khal,
Unfortunately, I don’t have and my access got expired.
All the best.
Hey I just finished this course as well online, but have never made an index before.
Would I be able to see yours to get a reference base on how to create my own?
Sent.
Hi, I am preparing for the exam. Will you be able to share with me your index? Thanks!
Sent it.
I am about to test for my exam, would you mind sharing your indexes with me? Would love to get a base.
Thanks for the write up!
Done
Can I also get a copy of your index?
Done
Hello,
I’m planning for the exam by end of year; appreciate if you can send me the index.
One more thing about labs, do you recommend an external resource for practicing them.
Thanks
Done
can u share the index?
Done
Hello,
I’m preparing to exam, appreciate if you share the index.
One more thing, do u recommend any external resource for practicing.
Thanks
Done
Mind sharing your index? I am taking this in December and feel like my index isn’t good enough. Thank you.
Done
Would you mind sharing your index(s) with me? Thank you!
Done
Just Completed this course through Ondemand. I here going through the Labs and exercises are the most important. should I spend most of my time reviewing labs, or just keep refining my index? can you also share your index? also, do you suggest any extra books or cheat sheets that I should take to the exam?
Labs are important but not mandatory… if you are fine and already have hands-on experience then no need for the labs.
You don’t need extra books, however supportive documents are good. Examples: TCP/UDP common ports, PE file format, Metasploit commands…etc.
I’ve sent you the index.
I’m also working towards the exam. Can you share your index?
done.
Could you please share your index also to me? Thank you in advance
Done.
This is a fantastic write up! I would love to compare your index with mine and see how it differs. Would you mind sharing it with me please?
Done
Hey Opaida. I’m compiling my own index as I’m going through the book but, if you don’t mind, would like to have yours to see if I missed something. Thank you in advance!
Done
Would you mind sharing your index(s) with me? Thank you!
Done
Could you please share your index(s) also to me? Thank you in advance
Done
I just tackled GCIH and I’m waiting for my advisory board invitation… They’re taking a couple of days as I get restless.. Can I get your index for GXPN for research and future attempts at it?
Done
Great review, thanks for sharing. Can I also get a copy of your GXPN index?
He man, thank you for the review it’s very useful.
I planned to pass the GXPN in 2 months and i wanna do my index based on the course.
can you please share your index with me to have an overview about how to do it.
thank you in advance.
Done
Could you please share your index with me? Thank you.
Done
Hi,
Great review. I am also preparing for the exam.
Could you share your index?
Thanks in advance
Done
Hi Opaida,
I was wondering if you’d be willing to share your index with me. I recently started my OnDemand edition, and am just now finishing up Section 1. While I have my OSCP etc., this is my first SANS course, so I’m not used to the exam format yet.
Thanks again, and congrats!
Hola,
Excellent review for GXPN, I’m taking the GXPN course and planning to present the exam in February, would you mind sharing your index with me? Gracias, I really appreciate it.
Also, any advise or recommendations when doing the CTF? I’m thinking of teaming up with some folks but any advise is recommended! Thanks, btw I’ve done GWAPT CTF and it was nice, I know how it works & stuff!.
Gracias
Hi Luis, I’ve sent the index.
For the CTF, really I’ve skipped all :)… so no recommendations.
Hi Opaida,
Nice review and kudos for becoming gxpn cert’ed.
Can I have your index as well, gonna take the exam in december?
Thanks upfront ;]
Thanks… I’ve sent the index to your email.. hope am not too late!.
Hi Opaida,
Thanks for your blog entry reviewing your GXPN experience. Great score..!!
I also happen to be trying to take the exam. Could you share your index with me too, please?
Thanks.. I’ve sent the index.
Thanks a lot for the review! I’m currently in section of of an on demand edition, and am loving the course so far.
I was wondering if you’d be willing to share your index with me as well. I already have my OSCP and eCPPT, but this is my first SANS course.
Thanks!
Done.
Hello,
This review is amazing. So I will take the exam on Nov 20,
Could you please share your index with me?
Done and sorry for being late!… I hope you made it.
Could please also share the index for me? I’ll take exam soon.
Done
Please share my the indexes, thanks so much!!! Have a nice day, bro!
Done.
Could you please share your index ?
Thanks!
Done.
Hey,
What about these 7 lab questions? Was it something straightforward like use metasploit and get some file from system or you had to write some custom buffer overflow to get the answer?
Are these 7 equally weighed as all other questions?
Could you share the index too please?
Hi,
Do you know if these 7 lab exams were equally weighted as all other questions? were these difficult lab exercise or something easy like running metaspoit and get some file?
Could you also share your index?
For the lab mark am not sure.
For the difficulty of the labs, just re-do the lab mentioned in the materials and you are fine.
Finally, I’ve sent you the index.
Thanks for sharing this review. Really helpful and encouraging! Would you also mind sharing your index? A bit worried I am missing a few. Thanks!
Done.
Hi,
Great post. I’d also like a copy of your index and any other references/books you feel comfortable about sharing them.
Done.
Hi, would you mind share the index? Thank you very much.
Done
Hi,
would you mind share the index?
Thank you very much.
Done
Hi, would you mind share the index?
Thank you.
Done
Hi Can I have the index please
Done.
would you please send me index for GXPN 660? I am taking the exam this month. Greatly appreciate your help.
Hi, do you mind sharing the index with me. I would like to compare when building my index to make sure I haven’t missed anything. Thank you.
Hi,
I am currently prepare my exam, would you please send the index for reference?
Thanks.
Could you please share your index with me?
Thank you very much!
Can I have your index please? Thanks
Great review, I have some certs (CEH, OSCP) but this is my first SANS one. I have been told there is now a practical section (hand on like OSCP) did you find this to be true?
I also would appreciate it too if you shared your index.
Yes it is there.. I remember almost 7 practical questions are there.
Hi,
Can you pls share the index.
Could you share your indeed with me as well? I sit for the exam in 4 days and want to make sure I haven’t missed anything.
Hi, great post.
I would like to see your index if is possible, it would be very appreciated.
Cheers
can you share your index please
Hi, congrats man. Can i get your index too, to compare it with mine?
Thanks
Great insights. Mind sharing your index please?
Hi, would you mind share the index? Thank you very much.
Mind sharing the index again? It was a great write up and you apparently know what you’re doing. I need all the help I can get
Hi, would you mind share the index?
Thank you and regards.
May I have the index please? Thank you so much.
Hi, would you be so kind to share the index with me please? thank you in advance.
Regards,
Steven
Hi. Thanks for the review. I plan on taking my exam next week. I just finished my index and decided to do some googling to see what else people made. Can you send me a copy of yours? Thanks!
Hi there!
Many thanks for sharing your experiences!
As others have done, can I also get a copy of your index please? 🙂
Hi. Thanks for sharing from your experience with GXPN. Could you share your index?
Thank!
Hi,
I’m taking the exam next month.
Mind to share your index
Looks like I may be a few months late to the party, but is there any chance I could also get a copy of your index?
I’ve actually got two already (one I created and one my buddy and I created), but would like to combine them into one. Neither of us have taken the exam yet, but we both will soon. It would be enlightening to compare ours to someone that has passed the exam. Thanks!
Thanks for the review as am getting closer for the exam could you please share the index
am sure its helpful, Thanks 🙂
Hi, would you also mind to share the index with me. Just prep. for the exam.
Many thanks for your help.
It looks like your index has been super popular. The ten days you put into it seems to have helped a lot of people. If you don’t mine sending it to me, I would love to take a look as well. Congrats on your attaining the certification. Cheers.
Thanks for the write up and info.
Any chance you can share your indexes with me please.
Toby.
Hi, great write up , thanks a lot to share . May you share the Index with me please, i have my exam in couple of weeks ?
It would be very nice of you , if you could search your index
Hello mate, thanks for the great review I have just finished the course and learned tons of things and willing to take the exam next month I was just asking if you could kindly share with me the indexes you used and thanks a lot
Hey, great write up. I will shortly be doing the exam. Could you share the index with me too? Thanks